View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001956 | T99X171.00 SKB Eagle | SW Issue | public | 2024-06-07 13:38 | 2024-06-24 09:30 |
| Reporter | (ALTech) Younkwang Jung | Assigned To | (SW) Kinbay Wu | Due Date | 2024-06-14 14:30 |
| Priority | normal | Severity | s4-minor | Reproducibility | have not tried |
| Status | closed | Resolution | fixed | ||
| Summary | 0001956: [Smart3] AVB key update patch | ||||
| Description | Hi Kinbay SoC mentions that there is an issue of factory initialization when upgrading to the replacement FW of AVB test key, and this issue has been resolved by each manufacturer. ( I'm guessing it's a Smart3 initial development issue and I'm not sure about it ) Attached here is the patch that I received from AML Kor and can be updated AB key without factory initialization. Please refer to the pdf document. 1. Apply the 0001 patch and find the new AVB test key's verified key hash 2. Include the value of the verified key hash in the code, as in the 0002 patch. In addition, it is said that you can contact Taiwan Amlogic FAE for this information. SoC recommends applying the patch, so please review if this is applicable to UI542. Thank you YK.Jung | ||||
| Tags | No tags attached. | ||||
| Attach Tags | |||||
| User List |
|
|---|
|
|
0001-debug-boot_param-v2015.patch (1,254 bytes)
From dfb0e57c388ed300680a678b487cbc6ad6bddaef Mon Sep 17 00:00:00 2001
From: Matthew Shyu <matthew.shyu@amlogic.com>
Date: Tue, 3 Jan 2023 08:35:36 +0000
Subject: [PATCH 1/2] debug boot_param v2015
Change-Id: I3d580b83e429071655c7d01bcee2f565e95406eA
---
common/cmd_bootm.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/common/cmd_bootm.c b/common/cmd_bootm.c
index 2f149cefe13..4ae7f9bc2ff 100644
--- a/common/cmd_bootm.c
+++ b/common/cmd_bootm.c
@@ -283,6 +283,20 @@ int do_bootm(cmd_tbl_t *cmdtp, int flag, int argc, char * const argv[])
memcpy(boot_params.verified_boot_hash, vbmeta_digest,
sizeof(boot_params.verified_boot_hash));
+ printf("device_locked = %d.\n", boot_params.device_locked);
+ printf("verified_boot_state = %d.\n", boot_params.verified_boot_state);
+ uint32_t i = 0;
+
+ printf("verified_boot_key\n");
+ for (i = 0; i < SHA256_DIGEST_SIZE; i++)
+ printf("%02x", boot_params.verified_boot_key[i]);
+
+ printf("\n");
+ printf("verified_boot_hash\n");
+ for (i = 0; i < SHA256_DIGEST_SIZE; i++)
+ printf("%02x", boot_params.verified_boot_hash[i]);
+ printf("\n");
+
if (set_boot_params(&boot_params) < 0) {
printf("failed to set boot params.\n");
}
--
2.29.0
0002-avb-force-test-key-1-1.patch (1,608 bytes)
From e895e90dadddcdd631419589d2e7a9f7e7361bcb Mon Sep 17 00:00:00 2001
From: Matthew Shyu <matthew.shyu@amlogic.com>
Date: Wed, 17 Jan 2024 19:38:12 -0800
Subject: [PATCH 2/2] avb: force test key [1/1]
PD#SWPL-154626
Problem:
For projects that uses test key to boot up but wish to change avb key
afterwards.
Solution:
For test key hash.
DANGEROUS:
THINK BEFORE YOU MERGE.
Verify:
Ohm
Change-Id: If975bf4f1d6d1b78556e000c2ba952d8d5e554b3
Signed-off-by: Matthew Shyu <matthew.shyu@amlogic.com>
---
lib/libavb/avb_slot_verify.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/lib/libavb/avb_slot_verify.c b/lib/libavb/avb_slot_verify.c
index 4429d4c824d..8790092881f 100644
--- a/lib/libavb/avb_slot_verify.c
+++ b/lib/libavb/avb_slot_verify.c
@@ -28,6 +28,14 @@
uint8_t boot_key_hash[AVB_SHA256_DIGEST_SIZE];
+#define FORCE_TEST_KEY (1)
+uint8_t test_key_hash[AVB_SHA256_DIGEST_SIZE] = {
+ 0x22, 0xde, 0x39, 0x94, 0x53, 0x21, 0x96, 0xf6,
+ 0x1c, 0x03, 0x9e, 0x90, 0x26, 0x0d, 0x78, 0xa9,
+ 0x3a, 0x4c, 0x57, 0x36, 0x2c, 0x7e, 0x78, 0x9b,
+ 0xe9, 0x28, 0x03, 0x6e, 0x80, 0xb7, 0x7c, 0x8c,
+};
+
static AvbSlotVerifyResult initialize_persistent_digest(
AvbOps* ops,
const char* part_name,
@@ -746,6 +754,10 @@ static AvbSlotVerifyResult load_and_verify_vbmeta(
avb_memcpy(boot_key_hash,
avb_sha256_final(&boot_key_sha256_ctx),
AVB_SHA256_DIGEST_SIZE);
+#if FORCE_TEST_KEY
+ avb_memcpy(boot_key_hash, test_key_hash,
+ AVB_SHA256_DIGEST_SIZE);
+#endif
}
}
}
--
2.29.0
|
|
|
Hi YK, According to AML Taiwan FAE, P1 patch is not a 'must'. If SKB asks to apply the patches, Fii will follow. Please help to check, thanks. |
|
|
Hi Kerwin This patch has nothing to do with SKB. Review it with Taiwan Amlogic FAE and if the patch does not need BFX-AT100, you don't have to apply it. Thank you YK.Jung |
|
|
There is no job to do. So I will close. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2024-06-07 13:38 | (ALTech) Younkwang Jung | New Issue | |
| 2024-06-07 13:38 | (ALTech) Younkwang Jung | Status | new => assigned |
| 2024-06-07 13:38 | (ALTech) Younkwang Jung | Assigned To | => (SW) Kinbay Wu |
| 2024-06-07 13:38 | (ALTech) Younkwang Jung | File Added: 0001-debug-boot_param-v2015.patch | |
| 2024-06-07 13:38 | (ALTech) Younkwang Jung | File Added: 0002-avb-force-test-key-1-1.patch | |
| 2024-06-07 13:38 | (ALTech) Younkwang Jung | File Added: Anrdoid R Hailstorm 4.1.1 SDK Mandatory Patch List avb2_testkey_replace P1 readme.pdf | |
| 2024-06-07 13:39 | (ALTech) Younkwang Jung | Issue Monitored: (ALTech) SY Yoon | |
| 2024-06-07 13:39 | (ALTech) Younkwang Jung | Issue Monitored: (ALTech) JunGyu Kim | |
| 2024-06-07 13:39 | (ALTech) Younkwang Jung | Issue Monitored: (ALTech) Wooshin Kang | |
| 2024-06-07 13:40 | (ALTech) Younkwang Jung | Issue Monitored: (ALTech) Sangmin Choi | |
| 2024-06-07 14:02 | (ALTech) Younkwang Jung | Issue Monitored: (ALTech) Jong-Hwa JUNG | |
| 2024-06-14 15:59 | (SW) Kerwin Chen | Note Added: 0016039 | |
| 2024-06-19 11:11 | (ALTech) Younkwang Jung | Summary | [Smart3] AB key update patch => [Smart3] AVB key update patch |
| 2024-06-19 12:17 | (ALTech) Younkwang Jung | Note Added: 0016066 | |
| 2024-06-24 09:30 | (ALTech) Wooshin Kang | Status | assigned => closed |
| 2024-06-24 09:30 | (ALTech) Wooshin Kang | Resolution | open => fixed |
| 2024-06-24 09:30 | (ALTech) Wooshin Kang | Note Added: 0016084 |